Security Engineer
Joppy
Barcelona, Spain
yesterday
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Shift work Languages
English Experience level
SeniorJob location
Barcelona, Spain
Tech stack
Amazon Web Services (AWS)
Software System Penetration Testing
Computer Programming
Django
Identity and Access Management
Python
PostgreSQL
Open Web Application Security
Phishing
Secure Coding
Security Software
Software Engineering
TypeScript
Software Vulnerability Management
Working Model 2D
Google Cloud Platform
React
Grafana
Software Security
Kubernetes
Gsuite
Front End Software Development
Terraform
ELK
Static Application Security Testing
Go
Dynamic Application Security Testing
Job description
- Enable the sales team to effectively answer security questionnaires for enterprise clients
- Work collaboratively within the SRE team, partnering with software engineering and other department leaders
- Reduce business risk by proactively preventing and responding to security incidents in a fast-scaling environment
What you'll do
- Security Engineering (60%)Harden AWS infrastructure, Kubernetes clusters, and application security
- Implement automated scanning (SAST/DAST) and dependency checks
- Strengthen authentication and identity management (SSO, MFA, Google Workspace)
- Set up vulnerability management and alerting, integrated with engineering sprints
- Respond to security incidents, create runbooks, and support customer security requests
- Security Culture & Training (40%)Develop and deliver engaging, role-specific training; run phishing simulations
- Define and enforce hardware and endpoint security standards
- Build a network of security champions and create self-service security guides
- Create pragmatic policies and governance that balance security with business needs
- AWS
- Infrastructure as Code: Terraform, Helm
- Monitoring: Grafana, ELK stack
- Frontend: React, TypeScript
Requirements
- 5+ years of experience in security engineering, infrastructure security, or security software engineering
- Hands-on expertise with AWS or GCP security (IAM, security groups, WAF, etc.)
- Deep understanding of application security (OWASP Top 10, secure coding, API security)
- Experience building security programs from the ground up in high-growth environments
- Track record in incident response and handling data breach scenarios
- Programming skills in at least one language: Python, TypeScript, or Golang
- Experience training employees on security best practices, * Experience with GDPR compliance and data protection regulations
- Background in penetration testing or offensive security
- Familiarity with Django, React, PostgreSQL, Terraform
- Experience responding to security questionnaires for enterprise sales
- Knowledge of SOC2 or ISO27001 implementation
- Vibrant office environment with complimentary drinks and snacks
Benefits & conditions
- Flexible hybrid working model with two remote days per week, plus 15 additional remote days per year
- Health insurance fully covered
- Discounted gym membership via Wellhub, with access to various gyms and wellbeing apps
- Collaborative, international team
- Paid sick leave to support your health
About the company
A fitness and wellness management software company that we partner with at Joppy is looking to hire a Senior Security Engineer to lead the security transformation and build security foundations from scratch.